SC-200 - Manage a Security Operations Environment (41% of the exam) - Section 1.3

Manage automated investigation and response, automatic attack disruption, Microsoft Sentinel automation rules, and playbooks.

Understand automated investigation and response (AIR) in Microsoft Defender XDR and how automatic attack disruption contains active attacks before an analyst intervenes. Configure Microsoft Sentinel automation rules to triage and route incidents, and build playbooks backed by Logic Apps connectors to orchestrate response actions across multiple services.

automated investigation and response (AIR)automatic attack disruption in Microsoft Defender XDRMicrosoft Sentinel automation rulesMicrosoft Sentinel playbooksLogic Apps connectors

Practice question for this objective

Free sampleManage a Security Operations Environmenthard

A security architect is enabling automatic attack disruption in Microsoft Defender XDR so that it can autonomously contain a confirmed human-operated ransomware attack across the estate. Endpoint signals are onboarded and automated investigation is running. The architect must ensure disruption is not blocked from taking its containment actions. Which configuration condition must be satisfied for the automatic disruption actions to be applied to the affected assets?

  • AA Microsoft Sentinel scheduled analytics rule must first be authored to detect the ransomware pattern before disruption can act on it
  • BDevices must keep an automation level enabled, because disruption is blocked where the device group is set to no automated remediation Correct
  • CAn analyst must approve each disruption action in the Action center before Microsoft Defender XDR applies it to a targeted device
  • DA custom detection rule must be created at the highest frequency so that disruption inherits its device-containment response action
Understand that automatic attack disruption uses the Defender for Endpoint automated response pipeline, so a no-automated-remediation device group blocks its containment actions. Automatic attack disruption is a built-in Microsoft Defender XDR capability that acts on high-confidence correlated signals to isolate devices and block accounts automatically. Because it applies device containment through the Microsoft Defender for Endpoint automated response path, a device group configured for no automated remediation prevents the disruption action from being applied. Keeping the automation level enabled lets disruption take its containment action.

Why A is wrong: Tempting because Sentinel often drives response, but attack disruption is a native Microsoft Defender XDR capability driven by high-confidence XDR signals, not by any Sentinel rule.

Why B is correct: Correct: disruption applies containment through the automated response pipeline, so a device group set to no automated remediation prevents the automatic actions from being applied.

Why C is wrong: Tempting because approvals exist for AIR remediations, but disruption is designed to act automatically without analyst approval; requiring approval would defeat its real-time purpose.

Why D is wrong: Tempting as custom detection rules can isolate devices, but disruption does not depend on a custom rule; it acts on built-in high-confidence correlated signals across XDR.

See more SC-200 practice questions, answers explained.

Exam traps in Manage a Security Operations Environment

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-200 bank for this domain.

  • The automation rule itself, which natively contains the connector actions to open tickets and post chat messages externally

    Why it is wrong: Tempting because automation rules do orchestrate responses, but they only perform in-Sentinel actions such as assign, tag, and status; they cannot call external connectors directly and must invoke a playbook.

  • Microsoft Sentinel Reader, because it grants visibility across incidents, hunting queries, and workbooks, which is the access a triage analyst needs to review and progress incidents during a shift.

    Why it is wrong: Microsoft Sentinel Reader is read-only; it lets the analyst view incidents, data, and workbooks but cannot change incident status, assign owners, or run playbooks, so it falls short of the triage actions the role requires.

  • Assign Microsoft Sentinel Contributor on the workspace to the on-call analysts, so that the people configuring the automation rule also hold the rights needed for it to invoke the playbook.

    Why it is wrong: Microsoft Sentinel Contributor lets users author rules and manage incidents, but the permission to run a playbook from an automation rule is held by the Sentinel service identity, not the analysts, and Contributor is far broader than least privilege requires for this task.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.